PT-2026-103990 · Getsimple Cms · Getsimplecms-Ce
CVE-2026-56661
·
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L |
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file get contents() after only format validation (FILTER VALIDATE URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getsimplecms-Ce